|
197421
|
6.1 |
MEDIUM
Physics
|
gnome centos
|
gnome-shell stream
|
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allo…
|
CWE-667
Improper Locking
|
CVE-2021-20315
|
2024-11-21 14:46 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197422
|
9.8 |
CRITICAL
Network
|
redhat
|
enterprise_linux
|
Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat En…
|
CWE-787 CWE-918
Out-of-bounds Write Server-Side Request Forgery (SSRF)
|
CVE-2021-20325
|
2024-11-21 14:46 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197423
|
7.4 |
HIGH
Network
|
linux fedoraproject debian netapp oracle
|
linux_kernel fedora debian_linux solidfire_\&_hci_management_node active_iq_unified_manager e-series_santricity_os_controller solidfire\ _enterprise_sds_\&_hci_storage_no…
|
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw al…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2021-20322
|
2024-11-21 14:46 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197424
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
fx3u-enet_firmware fx3u-enet-l_firmware fx3u-enet-p502_firmware
|
Improper initialization vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.16 and prior, FX3U-ENET-L Firmware version 1.16 and prior and FX3U-ENET-P502 Firmware version 1.16 and prior allo…
|
CWE-665
Improper Initialization
|
CVE-2021-20613
|
2024-11-21 14:46 |
2022-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197425
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
fx3u-enet_firmware fx3u-enet-l_firmware fx3u-enet-p502_firmware
|
Lack of administrator control over security vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.14 and prior, FX3U-ENET-L Firmware version 1.14 and prior and FX3U-ENET-P502 Firmware version…
|
NVD-CWE-Other
|
CVE-2021-20612
|
2024-11-21 14:46 |
2022-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197426
|
4.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configure…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2021-20148
|
2024-11-21 14:46 |
2022-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197427
|
5.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determin…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2021-20147
|
2024-11-21 14:46 |
2022-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197428
|
7.5 |
HIGH
Network
|
netgear
|
r6700_firmware
|
Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from the device's SOAP Interface (port 5000) is sent vi…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2021-20175
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197429
|
7.5 |
HIGH
Network
|
netgear
|
r6700_firmware
|
Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from the device's web interface is sent via HTTP, which …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2021-20174
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197430
|
8.8 |
HIGH
Network
|
netgear
|
r6700_firmware
|
Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system update check via the SOAP interface, the device is s…
|
CWE-78
OS Command
|
CVE-2021-20173
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|